2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41453 | MEDIUM | 4.8 | 0.3% | Jan 15, 2025 | A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr... |
| CVE-2024-39967 | MEDIUM | 6.5 | 0.3% | Jan 15, 2025 | Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command... |
| CVE-2024-36751 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL. |
| CVE-2024-48126 | CRITICAL | 9.8 | 0.4% | Jan 15, 2025 | HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service... |
| CVE-2024-48125 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via craft... |
| CVE-2024-48123 | HIGH | 8.4 | 0.2% | Jan 15, 2025 | An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via u... |
| CVE-2024-48122 | MEDIUM | 6.7 | 0.2% | Jan 15, 2025 | Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileg... |
| CVE-2024-48121 | MEDIUM | 6.5 | 0.2% | Jan 15, 2025 | The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi... |
| CVE-2024-54540 | MEDIUM | 4.3 | 0.2% | Jan 15, 2025 | The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc... |
| CVE-2024-54535 | MEDIUM | 4.3 | 0.4% | Jan 15, 2025 | A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ... |
| CVE-2024-54470 | MEDIUM | 4.6 | 0.3% | Jan 15, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPad... |
| CVE-2024-44136 | MEDIUM | 4.6 | 0.4% | Jan 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker... |
| CVE-2024-40854 | MEDIUM | 5.5 | 0.4% | Jan 15, 2025 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS ... |
| CVE-2024-40839 | LOW | 2.4 | 0.2% | Jan 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker... |
| CVE-2024-40771 | HIGH | 7.8 | 0.2% | Jan 15, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and... |
| CVE-2024-27856 | HIGH | 7.8 | 0.6% | Jan 15, 2025 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5... |
| CVE-2024-52005 | HIGH | 8.8 | 0.5% | Jan 15, 2025 | Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messa... |
| CVE-2024-7085 | HIGH | 8.2 | 0.4% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ S... |
| CVE-2024-57025 | MEDIUM | 6.8 | 1.3% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p... |
| CVE-2024-57024 | MEDIUM | 6.8 | 1.5% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute... |
| CVE-2024-57023 | MEDIUM | 6.8 | 1.3% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p... |
| CVE-2024-57022 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" ... |
| CVE-2024-57021 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" ... |
| CVE-2024-57020 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute... |
| CVE-2024-57019 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now